CVE-2026-11326

Published Jun 5, 2026

Last updated 2 months ago

Overview

Description
OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in forum.openai.com could be used to access these functions, allowing access to browser history information and the ability to open or close tabs. OpenAI Atlas 1.2025.288.15 narrows access to these APIs to *.chatgpt.com; users should upgrade to 1.2025.288.15 or later.
Source
8f4f43ab-ba69-4d92-aa1d-d772184d6fb7
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
6
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:L/U:Green
Severity
MEDIUM

Weaknesses

8f4f43ab-ba69-4d92-aa1d-d772184d6fb7
CWE-284

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.